CHAPTER 2: PRODUCT DESCRIPTION
SECURITY
L60 LINE PHASE COMPARISON SYSTEM – INSTRUCTION MANUAL
2-5
2
When entering a settings or command password via EnerVista or any serial interface, the user must enter the
corresponding connection password. If the connection is to the back of the L60, the remote password must be used. If the
connection is to the RS232 port of the faceplate, the local password applies.
Password access events are logged in the Event Recorder.
2.2.0.3 CyberSentry security
CyberSentry embedded security is a software option that provides advanced security services. When this option is
purchased, the basic password security is disabled automatically.
CyberSentry provides security through the following features:
•
An Authentication, Authorization, Accounting (AAA) Remote Authentication Dial-In User Service (RADIUS) client that is
centrally managed, enables user attribution, provides accounting of all user activities, and uses secure standards-
based strong cryptography for authentication and credential protection
•
A Role-Based Access Control (RBAC) system that provides a permission model that allows access to UR device
operations and configurations based on specific roles and individual user accounts configured on the AAA server (that
is, Administrator, Supervisor, Engineer, Operator, Observer roles)
•
Security event reporting through the Syslog protocol for supporting Security Information Event Management (SIEM)
systems for centralized cybersecurity monitoring
•
Strong encryption of all access and configuration network messages between the EnerVista software and UR devices
using the Secure Shell (SSH) protocol, the Advanced Encryption Standard (AES), and 128-bit keys in Galois Counter
Mode (GCM) as specified in the U.S. National Security Agency Suite B extension for SSH and approved by the National
Institute of Standards and Technology (NIST) FIPS-140-2 standards for cryptographic systems
Example:
Administrative functions can be segmented away from common operator functions, or engineering type access,
all of which are defined by separate roles (see figure) so that access of UR devices by multiple personnel within a
substation is allowed. Permissions for each role are outlined in the next section.
Figure 2-3: CyberSentry user roles
The following types of authentication are supported by CyberSentry to access the UR device:
•
Device Authentication (local UR device authenticates)
•
Server Authentication (RADIUS server authenticates)
The EnerVista software allows access to functionality that is determined by the user role, which comes either from the local
UR device or the RADIUS server.
The EnerVista software has a device authentication option on the login screen for accessing the UR device. When the
"Device" button is selected, the UR uses its local authentication database and not the RADIUS server to authenticate the
user. In this case, it uses its built-in roles (Administrator, Engineer, Supervisor, Observer, Operator) as login names and the
associated passwords are stored on the UR device. As such, when using the local accounts, access is not user-attributable.
In cases where user-attributable access is required especially to facilitate auditable processes for compliance reasons, use
RADIUS authentication only.
When the "Server" Authentication Type option is selected, the UR uses the RADIUS server and not its local authentication
database to authenticate the user.
842838A2.CDR
Administrator
Engineer
Supervisor
Operator
Observer